MALICIOUS — 5dfe374d510b4b7a6e1fbf6b52ed61dcf0b40e412d92dd97d6adb4a0b9f7482e
MALICIOUS — 5dfe374d510b4b7a6e1fbf6b52ed61dcf0b40e412d92dd97d6adb4a0b9f7482e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Delf family. 12 of 51 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
5dfe374d510b4b7a6e1fbf6b52ed61dcf0b40e412d92dd97d6adb4a0b9f7482e - SHA-1:
a6082e3977df5ab9ee0be15ff56d7b532c54ceee - MD5:
ac366f5b559f73fb7a09a21b397483c0 - imphash:
31d1c48ee7d8e07a5706e963146db875 - ssdeep:
196608:ACzNA7rlvRz1rrFBV6tpjuj6gYPKHCKsd:AjUtYj6gYPYc - TLSH:
T1706759CC022E1746DDA1D92524048EBF1D98B7D6347AE9F80B50A8F131C6777BA350BA - Submitted as: 5dfe374d510b4b7a6e1fbf6b52ed61dcf0b40e412d92dd97d6adb4a0b9f7482e
- File type: pe · Size: 6814448 bytes
- Verdict: malicious (100/100) · Family: Delf
Detections (12 of 51 engines)
- YARA: MalwareAnalyser built-in: Suspicious_PowerShell_Download_Exec
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Trojan.Delf-1564
- YARA: bartblaze: BB_Vjw0rm_Houdini
- YARA: delivr.to detections: DLV_LNK_PowerShell_Launcher
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: MalwareAnalyser community pack: TL_Suspicious_PowerShell_Download
- Microsoft Defender: Virus:Win32/Viking.JX
- Emsisoft (Emergency Kit): Dropped:Generic.Malware.PWBPk!.69063F94
- Kaspersky (KVRT): Virus.Win32.Delf.62976
MITRE ATT&CK
YARA
- Suspicious_PowerShell_Download_Exec
- Windows_Injection_Api_Combo
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Delf-1564 (rule
Win.Trojan.Delf-1564) - engine signal, weight 0.90, confidence 0.95 - Encoded/hidden PowerShell download-and-exec (rule
Suspicious_PowerShell_Download_Exec) - yara signal, weight 0.70, confidence 0.90 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: bartblaze flagged BB_Vjw0rm_Houdini (rule
BB_Vjw0rm_Houdini) - engine signal, weight 0.35, confidence 0.70 - YARA: delivr.to detections flagged DLV_LNK_PowerShell_Launcher (rule
DLV_LNK_PowerShell_Launcher) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Suspicious_PowerShell_Download (rule
TL_Suspicious_PowerShell_Download) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://chocolatey.org/api/v2/, https://chocolatey.org/packages/checksum, https://chocolatey.org/docs/automatic-packages - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/2001/XMLSchema-instance
- https://github.com/chocolatey/choco/issues/1206
- https://github.com/chocolatey/choco/issues/1292#issuecomment-304068121
- http://msdn.microsoft.com/en-us/library/system.consolecolor
- https://chocolatey.org/api/v2/
- https://github.com/chocolatey/chocolatey
- http://www.apache.org/licenses/LICENSE-2.0
- https://chocolatey.org/packages/checksum
- https://chocolatey.org/docs/automatic-packages
- https://support.microsoft.com/en-us/kb/811833
- https://sevenzip.osdn.jp/chm/general/formats.htm
- https://somelocation.com/
- https://somelocation.com/thefile.exe
- http://stackoverflow.com/questions/265339/whats-the-best-way-to-automate-secure-ftp-in-powershell
- http://poshcode.org/417
- http://pwnt.co
- https://chocolatey.org/docs/features-private-cdn
- https://github.com/chocolatey/choco/issues/1800#issuecomment-484293844
- http://msdn.microsoft.com/en-us/library/windows/desktop/ms724832
- https://chocolatey.org/compare
- http://stackoverflow.com/questions/518181/too-many-automatic-redirections-were-attempted-error-message-when-using-a-httpw
- http://learn-powershell.net/2013/02/08/powershell-and-events-object-events/
- http://msdl.microsoft.com/download/symbols
- https://somewhere.com/file.msi
- https://somewhere.com/file-x64.msi
Embedded domains
- www.w3.org
- choco.app
- github.com
- msdn.microsoft.com
- chocolatey.org
- www.apache.org
- support.microsoft.com
- sevenzip.osdn.jp
- somelocation.com
- stackoverflow.com
- poshcode.org
- pwnt.co
- learn-powershell.net
- msdl.microsoft.com
- somewhere.com
- stexbar.googlecode.com
- cdn.rubyinstaller.org
- technet.microsoft.com
- powershell.com
- visualstudiogallery.msdn.microsoft.com
- download.sysinternals.com
- nsis.sourceforge.net
- www.jrsoftware.org
- www.jeremyskinner.co.uk
- www.gnu.org
Embedded IP addresses
- 192.168.0.30
- 192.168.8.1
- 0.10.6.1
- 0.9.10.1
- 0.8.2.0
- 0.10.15.0
- 0.9.10.0
- 0.9.9.6
- 0.9.8.32
- 0.9.9.9
Registry keys
- HKLM\System\CurrentControlSet\Control\Session
- HKCU\Environment
File paths
- c:\someFile.zip
- C:\Windows\System32\config\systemprofile\AppData\Local\Temp,
- C:\Windows\SysWOW64\...
- C:\somepath\somename.exe
- C:\tools\NHibernatProfiler\nhprof.exe
- d:\oracle\jdk\bin
- f:\localsymbols
- C:\Full\Path\To\msiexec.exe
- c:\path\setup.exe
- C:\test.lnk
- C:\text.exe
- C:\test.exe
- C:\notepad.lnk
- C:\Windows\System32\notepad.exe
- C:\test.txt
- C:\test.ico
- c:\$($env:chocolateyPackageName)_msi_install.log`
- C:\User\Username\AppData\Local\Temp`).
- c:\program
- c:\borrar\EmptyDll\Release\EmptyDll.pdb
- X:\:`:d:h:
- X:\:`:d:h:l:p:t:x:
- T:\:d:p:
- X:\:`:
- T:\:d:l:t:
More Delf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report